FBI Arrests Another ShinyHunters Suspect
The FBI has arrested a second suspected ShinyHunters member in days, as the agency escalates pressure on the gang behind its breach.
The FBI's hunt for the ShinyHunters extortion crew has produced another arrest, this time of a suspect the bureau describes as a primary co-conspirator in the intrusion into its own systems. The arrest, announced Friday by FBI Director Kash Patel, marks the latest move in a widening crackdown that has already touched the Netherlands and Jordan.
Patel said the suspect was taken into custody in connection with the breach of FBIJobs.gov, a platform the FBI has said was managed by a third-party vendor. Neither the suspect's name nor the location of the arrest was disclosed in Patel's statement, leaving key details of the case still under seal.
According to The New York Times, the suspect is a Canadian citizen arrested in Pennsylvania and is considered a primary co-conspirator in the intrusion. The FBI has not publicly confirmed those details, and no charges have been announced.
Arrest Follows a String of Moves
The arrest is the latest in a series of law enforcement actions against ShinyHunters, which claimed responsibility for breaching FBI systems. The group told BleepingComputer in September that it accessed the agency's systems by exploiting an alleged Oracle PeopleSoft zero-day vulnerability, then moved laterally into FBI-managed AWS GovCloud infrastructure.
ShinyHunters claimed to have stolen between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, medical and psychiatric records, and internal service records. Data samples shared with BleepingComputer and other outlets confirmed the exposure of home addresses, Social Security numbers, sensitive job assignments, information about employees' family members, and other personal data.
The FBI has since said the incident stemmed from a third-party contractor-managed platform that failed to install a security update. An internal FBI memo said the agency assumed the breach affected all employees, according to the NY Times.
Dutch Arrest Tested the Group's Story
The pressure campaign began in earnest on September 15, when Dutch police arrested a 24-year-old Amsterdam man as part of an investigation into the hacking group. The suspect was identified as Pepijn van der Stap, a Dutch hacker previously known online as "Umbreon."
ShinyHunters denied any connection to van der Stap, telling BleepingComputer at the time, "That individual has no association with us. Frankly, we are laughing."
The public denial did not slow the FBI's efforts. The bureau soon took the unusual step of publicly warning ShinyHunters members to turn themselves in, saying investigators were continuing to identify people involved with the group.
"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left."
— Brett Leatherman, Assistant Director of the FBI Cyber Division
Leatherman added: "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."
Jordan Detention and a Vanishing Contact
Days after that warning, a suspected ShinyHunters member known online as "Rey" was reportedly detained in Jordan and began cooperating with the FBI and international law enforcement agencies. Reuters reported that Jordanian authorities detained Rey, identified as Saif al-Din Khader, and that sources said he was aiding investigators in finding other alleged members of the group.
Around the same time, signs of disruption began appearing within ShinyHunters. The group's main representative, who had regularly communicated with BleepingComputer and other reporters and had intimate knowledge of ShinyHunters' attacks over the past two years, stopped responding on Telegram. That account now appears to have been deleted.
The same representative had continued communicating with BleepingComputer after van der Stap's arrest, suggesting van der Stap was not the person operating the account. Around the time of Rey's detention, another alleged ShinyHunters affiliate with knowledge of the FBI hack shut down an online messaging account, and the group's data leak site went offline. A new leak site later launched, suggesting at least some members remained active.
It is unclear whether the disappearance of the group's main representative is connected to any of the recent arrests.
"We will continue to work closely with our partners to disrupt what's left of the ShinyHunters group and their associates, no matter where they operate," Patel said Friday.
Who Is ShinyHunters?
ShinyHunters is an extortion group known for stealing data from web applications and cloud-based SaaS platforms, then demanding ransom payments from victim organizations under threat of leaking the stolen data. The ShinyHunters name has been tied to numerous threat actors involved in data breaches dating back to at least 2018.
Over the past two years, hackers operating under the ShinyHunters name have become particularly active, conducting data theft and extortion campaigns against organizations worldwide. Recent campaigns have targeted Salesforce and other cloud SaaS environments, with the threat actors linked to breaches affecting companies including Google, Cisco, PornHub, and online dating giant Match Group.
In some attacks, the group breached third-party integration companies and stole authentication tokens that attackers could then use to access connected SaaS environments and steal customer data. More recently, ShinyHunters has run voice phishing (vishing) campaigns targeting Okta, Microsoft, and Google single sign-on (SSO) accounts, impersonating IT support personnel to trick employees into entering credentials and multi-factor authentication (MFA) codes into phishing sites.
As BleepingComputer first reported, the group has also used device code vishing attacks to steal Microsoft account authentication tokens. Once they obtain credentials and authentication codes, the attackers use compromised SSO accounts to access connected enterprise platforms, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
ShinyHunters was also behind a massive data-theft attack on Instructure Canvas in May that caused significant outages across the platform. Instructure later reached an "agreement" with the threat actors to prevent them from publishing data stolen in the breach.
In addition to conducting its own breaches, ShinyHunters also operated as an extortion-as-a-service group, helping other threat actors extort organizations they had compromised.
- Between 2TB and 3TB of data claimed stolen from FBI systems
- 24-year-old Amsterdam man arrested September 15
- ShinyHunters name tied to data breaches dating back to at least 2018
What the Crackdown Means for Defenders
For security teams, the takeaway is less about any single arrest and more about the operational patterns that made ShinyHunters effective. The group's reliance on third-party integration tokens and SSO credentials means that even organizations with strong perimeter defenses can be exposed through a compromised vendor or a single phished employee. The FBI's own breach, which the bureau attributes to a contractor-managed platform that missed a security update, is a case in point.
Businesses that rely on SaaS platforms should treat third-party integrations as part of their attack surface. That means auditing which applications have access to core systems, enforcing MFA everywhere it is supported, and training employees to recognize vishing attempts that impersonate IT support. The group's use of device code phishing to steal Microsoft tokens shows that attackers are willing to chain multiple techniques to reach their targets.
The arrests may disrupt the group's operations, but the ShinyHunters name has survived previous law enforcement actions. Cybercriminals have continued to operate under the same banner even after suspects were detained in cases tied to Snowflake data-theft attacks, PowerSchool breaches, and the Breached v2 hacking forum. That history suggests that while individual arrests can slow operations, they do not necessarily end them.
Whether the latest arrest leads to charges or further cooperation remains to be seen. For now, the FBI is signaling that it intends to keep up the pressure, and organizations that rely on cloud and SaaS infrastructure would be wise to assume that the tactics ShinyHunters pioneered will outlast any single crew.
Sources
- BleepingComputer Original source
- The New York Times reports Also reporting
- hacking group breached FBI systems Also reporting
- Dutch police arrested a 24-year-old Amsterdam man Also reporting
- publicly warning ShinyHunters members to turn themselves in Also reporting
- reportedly detained in Jordan Also reporting
Continue Reading
GhostAction Returns, Hits 340+ Maintainer Repos
A credential-theft campaign has compromised two open-source maintainer accounts to push malicious GitHub Actions workflows into more than 340 repositories.
DarkSword Kit Grows a Wallet-Stealing Arm
A new P7 DarkSword variant trims its on-device footprint while adding keychain theft, crypto-wallet extraction, and two-way command control.
YMCO Leader Pleads Guilty in Mule Case
A dual citizen admits to running a 15,000-mule money laundering network that moved millions for cybercriminals over nearly two decades.